![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I have followed the removal guide to the letter and I am still getting the trojan downloader BHO.BHG or BHO.BGL thing anytime I hit a webpage, its making my AVG work overtime. I am also getting website redirects. I did have the virtumonde thing and tried the alternative scan for that, it keeps trying to fix the same thing every time I reboot.
the spybot scan: "couldn't fix all problems, associated files in use (memory)", I never saw that before. Attached are the requested files when asking for help, everything was done in order. I appreciate any help that you folks could provide and thank you in advance. Brian |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Additional scans requested
note, the AVG scan saved in the .tab format, it will not upload. Thanks in advance Brian |
|
#3
|
||||
|
||||
|
Quote:
You have a multi-layered set of Vundo infections. Download this file - combofix.exe
Do not mouseclick combofix's window while it is running. That may cause it to stall. Now uninstall the below old version of Sun Java which could have been the cause for Vundo sneaking in: Java 2 Runtime Environment, SE v1.4.2_03 Now attach the below new logs and tell me how the above steps went.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#4
|
|||
|
|||
|
Quote:
I followed your instructions and am attaching what you asked for. Things seem to be running better, I am gageing this on not having my AVG virus detection window popping up every few seconds now. I still can not remove one of my programs that I want to get rid of, Stronghold Crusader, a game my kids installed. Every time I try (even now) to remove it through windows add/remove, it stays. Would you think this is a related problem? Once again, thank you for all your help. Brian |
|
#5
|
|||
|
|||
|
combofix log attached.
|
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Doing an AVG scan, its still picking up the BHO.BGL trojan. So I think its still lurking around....
|
|
#7
|
||||
|
||||
|
Quote:
Let's continue with your malware removal.
Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: (no name) - {19E6495C-513C-4D61-9A3B-9FBD04E8CFC3} - C:\WINDOWS\system32\hwcgwtdt.dll (file missing) O2 - BHO: (no name) - {52706EF7-D7A2-49AD-A615-E903858CF284} - (no file) O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing) After clicking Fix, exit HJT. Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
Quote:
Now attach the below new logs and tell me how the above steps went.
Make sure you tell me how things are working now! Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#8
|
|||
|
|||
|
First three attached
|
|
#9
|
|||
|
|||
|
HJT attached as requested.
I'll check to see how things are running and post back. Thanks Chaslang!! |
|
#10
|
||||
|
||||
|
Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Chaslang,
Thanks a million!!!! Everything seems to be in fine working order now and I followed your post infection guidance to hopefully preclude any new incursions. I don't know how to thank you enough!! Brian |
|
#12
|
||||
|
||||
|
You're welcome. Surf safely!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Completed the Malware removal guide... | zanni | Malware Removal | 4 | 05-17-07 17:52 |
| I've completed the required steps for malware removal...now what? | keith h | Malware Removal | 5 | 07-07-06 12:46 |
| Malware Help:All steps completed, Just making sure... | t3hCyborg | Malware Removal | 7 | 05-27-06 11:37 |
| Completed 7 Steps - still problems | jimogrady | Malware Removal | 6 | 03-17-06 20:50 |
| Ad problems, FAQ steps completed | MichaelReb | Malware Removal | 2 | 01-03-05 12:54 |